US7596531B2

Method and apparatus for protecting against side channel attacks against personal identification numbers

Summary by NHIP

Secure PIN Management Method

The method manages personal identification numbers in a secure portable device by scrambling and comparing PINs using specific keys. Distinctive elements include storing a second scrambled PIN in an EEPROM field, marking it untested, and validating it by comparing a newly created scrambled version against a received one.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A method for private personal identification number (PIN) management includes receiving a first PIN, receiving a first key used to scramble a second PIN that has been validated, receiving a first scrambled PIN comprising the second PIN scrambled with the first key, scrambling the first PIN with the first key to create a second scrambled PIN and validating the first PIN based at least in part on whether the first scrambled PIN matches the second scrambled PIN.

US7596531B2, drawing sheet 1
Sheet 1 of 35

Term

Term ended

Expired 8 July 2026, 0.2 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

33 claims: 3 independent, 30 dependent

  1. 1
    Broadest claimClaim Score 44, average(NHIP)A method for private personal identification number (PIN) management in a secure portable device having (1) executable instructions stored therein and (2) a processor wherein execution of said executable instructions on said processor provides the method comprising:receiving, by said processor, a first PIN;receiving, by said processor, a first key;receiving, by said processor, a first scrambled PIN;creating, by said processor, a second scrambled PIN by scrambling said first PIN with a second key;storing, by said processor, said second scrambled PIN in a field in a memory of said secure portable device;marking, by said processor, a test field, in said memory, for said stored second scrambled PIN as untested;creating, by said processor, a third scrambled PIN by scrambling said first PIN with said first key;comparing, by said processor, said first scrambled PIN with said third scrambled PIN;and marking, by said processor, said test field for said stored second scrambled PIN based at least in part on said comparing said first scrambled PIN with said third scrambled PIN.
  2. 9
    A program storage device readable by a machine, embodying a program of instructions executable by a secure portable device to perform a method for private personal identification number (PIN) management wherein execution of said program of instructions by a processor on said secure portable device causes the secure portable device to perform the method comprising:receiving, by said processor, a first PIN;receiving, by said processor, a first key;receiving, by said processor, a first scrambled PIN;creating, by said processor, a second scrambled PIN by scrambling said first PIN with a second key;storing, by said processor, said second scrambled PIN in a field in a memory of said secure portable device;marking, by said processor, a test field, in said memory, for said stored second scrambled PIN as untested;creating, by said processor, a third scrambled PIN by scrambling said first PIN with said first key;comparing, by said processor, said first scrambled PIN with said third scrambled PIN;and marking, by said processor, said test field for said stored second scrambled PIN based at least in part on said comparing said first scrambled PIN with said third scrambled PIN.
  3. 17
    An apparatus for private personal identification number (PIN) management, the apparatus comprising:a memory for storing at least one key, at least one scrambled PIN, and at least one validity indication;a processor;and executable instructions stored on said apparatus, wherein execution of said executable instructions on said processor causes the processor to perform the method including: receiving, by said processor, a first PIN;receiving, by said processor, a first key;receiving, by said processor, a first scrambled PIN;creating by said processor, a second scrambled PIN by scrambling said first PIN with a second key;storing, by said processor, said second scrambled PIN in a field in memory of said secure portable device;marking, by said processor, a test field, in said memory, for said stored second scrambled PIN as untested;creating by said processor, a third scrambled PIN by scrambling said first PIN with said first key;comparing, by said processor, said first scrambled PIN with said third scrambled PIN;and marking, by said processor, said test field for said stored second scrambled PIN based at least in part on said comparing said first scrambled PIN with said third scrambled PIN.